分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp02-1 | 2024-04-18 10:31:15 | 2024-04-18 10:33:30 | 135 秒 |
文件名 | synergy-11.exe |
---|---|
文件大小 | 4499456 字节 |
文件类型 | PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows |
MD5 | 1159402c8c35af34671dcdfec6a5fb94 |
SHA1 | 5a9cbb7f26829d5a4a2932602bb003ad335e0cc3 |
SHA256 | 9786f26a4d43134f538119ea4be82b034ce41189b35460c8bebcdbbf2c4f9ad3 |
SHA512 | caa8da5a72b66dfe261f6ab1b6cf15217479567e4441c44d8df4f3055b9c222fe5170e932102caf92c9d8588003eb31d2690c7b406dd9b5c27dd143bad2191e2 |
CRC32 | B55B7181 |
Ssdeep | 49152:aK/kIp/Yb/mhIa1UNy8pjBiQPZguEonwrZDMeIU0uQR6oz0l+tyoJBy7PQF5j1xh:VH2Xpj8Qd0rBoR9XkZ+ |
Yara | 登录查看Yara规则 |
找不到该样本 提交误报 |
无主机纪录.
无域名信息.
初始地址 | 0x140000000 |
---|---|
入口地址 | 0x1400014d0 |
声明校验值 | 0x004517f5 |
实际校验值 | 0x004517f5 |
最低操作系统版本要求 | 4.0 |
编译时间 | 2024-04-18 10:27:25 |
载入哈希 | 9c44e617aad18f30b2dc617ac77baf67 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x003155d8 | 0x00315600 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.21 |
.data | 0x00317000 | 0x00003430 | 0x00003600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 1.95 |
.rdata | 0x0031b000 | 0x000f3a60 | 0x000f4000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.73 |
.pdata | 0x0040f000 | 0x00016c44 | 0x00016e00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 6.33 |
.xdata | 0x00426000 | 0x0001a1f8 | 0x0001a200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.75 |
.bss | 0x00441000 | 0x00000ae0 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
.idata | 0x00442000 | 0x00003420 | 0x00003600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 4.53 |
.CRT | 0x00446000 | 0x00000070 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.49 |
.tls | 0x00447000 | 0x00000010 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
.rsrc | 0x00448000 | 0x000004e8 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 4.78 |
.reloc | 0x00449000 | 0x00008794 | 0x00008800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 5.47 |
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49160 | 23.206.229.108 | 80 |
192.168.122.202 | 49181 | 192.168.122.201 | 445 |
192.168.122.202 | 49182 | 192.168.122.201 | 445 |
192.168.122.202 | 49183 | 192.168.122.201 | 445 |
192.168.122.202 | 49184 | 192.168.122.201 | 445 |
192.168.122.202 | 49185 | 192.168.122.201 | 445 |
192.168.122.202 | 49186 | 192.168.122.201 | 445 |
192.168.122.202 | 49187 | 192.168.122.201 | 445 |
192.168.122.202 | 49188 | 192.168.122.201 | 445 |
192.168.122.202 | 49189 | 192.168.122.201 | 445 |
192.168.122.202 | 49190 | 192.168.122.201 | 445 |
192.168.122.202 | 49191 | 192.168.122.201 | 445 |
192.168.122.202 | 49192 | 192.168.122.201 | 445 |
192.168.122.202 | 49193 | 192.168.122.201 | 445 |
192.168.122.202 | 49194 | 192.168.122.201 | 135 |
192.168.122.202 | 49195 | 192.168.122.201 | 49156 |
192.168.122.202 | 49196 | 192.168.122.201 | 445 |
192.168.122.202 | 49197 | 192.168.122.201 | 445 |
192.168.122.202 | 49198 | 192.168.122.201 | 445 |
192.168.122.202 | 49199 | 192.168.122.201 | 445 |
192.168.122.202 | 49200 | 192.168.122.201 | 445 |
192.168.122.202 | 49201 | 192.168.122.201 | 445 |
192.168.122.202 | 49202 | 192.168.122.201 | 445 |
192.168.122.202 | 49203 | 192.168.122.201 | 445 |
192.168.122.202 | 49204 | 192.168.122.201 | 445 |
192.168.122.202 | 49205 | 192.168.122.201 | 445 |
192.168.122.202 | 49206 | 192.168.122.201 | 445 |
192.168.122.202 | 49207 | 192.168.122.201 | 445 |
192.168.122.202 | 49208 | 192.168.122.201 | 445 |
192.168.122.202 | 49209 | 192.168.122.201 | 445 |
192.168.122.202 | 49210 | 192.168.122.201 | 445 |
192.168.122.202 | 49211 | 192.168.122.201 | 445 |
192.168.122.202 | 49212 | 192.168.122.201 | 49156 |
192.168.122.202 | 49213 | 192.168.122.201 | 445 |
192.168.122.202 | 49215 | 192.168.122.201 | 445 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 63246 | 192.168.122.1 | 53 |
无域名信息.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49160 | 23.206.229.108 | 80 |
192.168.122.202 | 49181 | 192.168.122.201 | 445 |
192.168.122.202 | 49182 | 192.168.122.201 | 445 |
192.168.122.202 | 49183 | 192.168.122.201 | 445 |
192.168.122.202 | 49184 | 192.168.122.201 | 445 |
192.168.122.202 | 49185 | 192.168.122.201 | 445 |
192.168.122.202 | 49186 | 192.168.122.201 | 445 |
192.168.122.202 | 49187 | 192.168.122.201 | 445 |
192.168.122.202 | 49188 | 192.168.122.201 | 445 |
192.168.122.202 | 49189 | 192.168.122.201 | 445 |
192.168.122.202 | 49190 | 192.168.122.201 | 445 |
192.168.122.202 | 49191 | 192.168.122.201 | 445 |
192.168.122.202 | 49192 | 192.168.122.201 | 445 |
192.168.122.202 | 49193 | 192.168.122.201 | 445 |
192.168.122.202 | 49194 | 192.168.122.201 | 135 |
192.168.122.202 | 49195 | 192.168.122.201 | 49156 |
192.168.122.202 | 49196 | 192.168.122.201 | 445 |
192.168.122.202 | 49197 | 192.168.122.201 | 445 |
192.168.122.202 | 49198 | 192.168.122.201 | 445 |
192.168.122.202 | 49199 | 192.168.122.201 | 445 |
192.168.122.202 | 49200 | 192.168.122.201 | 445 |
192.168.122.202 | 49201 | 192.168.122.201 | 445 |
192.168.122.202 | 49202 | 192.168.122.201 | 445 |
192.168.122.202 | 49203 | 192.168.122.201 | 445 |
192.168.122.202 | 49204 | 192.168.122.201 | 445 |
192.168.122.202 | 49205 | 192.168.122.201 | 445 |
192.168.122.202 | 49206 | 192.168.122.201 | 445 |
192.168.122.202 | 49207 | 192.168.122.201 | 445 |
192.168.122.202 | 49208 | 192.168.122.201 | 445 |
192.168.122.202 | 49209 | 192.168.122.201 | 445 |
192.168.122.202 | 49210 | 192.168.122.201 | 445 |
192.168.122.202 | 49211 | 192.168.122.201 | 445 |
192.168.122.202 | 49212 | 192.168.122.201 | 49156 |
192.168.122.202 | 49213 | 192.168.122.201 | 445 |
192.168.122.202 | 49215 | 192.168.122.201 | 445 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 63246 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Protocol | SID | Signature | Category |
---|---|---|---|---|---|---|---|---|
2024-04-18 10:33:01.716820+0800 | 192.168.122.202 | 49183 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.726844+0800 | 192.168.122.202 | 49187 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:05.106570+0800 | 192.168.122.202 | 49192 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:08.420673+0800 | 192.168.122.202 | 49205 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.860451+0800 | 192.168.122.202 | 49211 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.575740+0800 | 192.168.122.202 | 49203 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:04.704927+0800 | 192.168.122.202 | 49189 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.586299+0800 | 192.168.122.202 | 49182 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.975677+0800 | 192.168.122.202 | 49184 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.080202+0800 | 192.168.122.202 | 49196 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:05.210323+0800 | 192.168.122.202 | 49193 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.491077+0800 | 192.168.122.202 | 49206 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.426291+0800 | 192.168.122.202 | 49186 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.805406+0800 | 192.168.122.202 | 49198 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.761681+0800 | 192.168.122.202 | 49208 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:05.015226+0800 | 192.168.122.202 | 49191 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:03.369155+0800 | 192.168.122.202 | 49188 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.204957+0800 | 192.168.122.202 | 49201 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.013355+0800 | 192.168.122.202 | 49199 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.772517+0800 | 192.168.122.202 | 49209 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.102961+0800 | 192.168.122.202 | 49181 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.309362+0800 | 192.168.122.202 | 49202 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:10.617593+0800 | 192.168.122.202 | 49215 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.144661+0800 | 192.168.122.202 | 49185 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.390986+0800 | 192.168.122.202 | 49197 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.665140+0800 | 192.168.122.202 | 49207 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:04.997939+0800 | 192.168.122.202 | 49190 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.117727+0800 | 192.168.122.202 | 49200 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.853010+0800 | 192.168.122.202 | 49210 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:10.244047+0800 | 192.168.122.202 | 49213 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.806057+0800 | 192.168.122.202 | 49204 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 744065 |
---|---|
Mongo ID | 662086c6dc327b6543622de0 |
Cuckoo release | 1.4-Maldun |